supply-chain
Safeguard articles tagged "supply-chain" — guides, analysis, and best practices for software supply chain and application security.
859 articles
SCA Solution: How to Choose Software Composition Analysis
An SCA solution inventories your open-source dependencies and flags the ones with known vulnerabilities or risky licenses. Here is what separates a good one.
GitHub Actions Supply Chain Security: A 2026 Hardening Guide
GitHub Actions runs with your secrets and write access to your repo. This guide maps the real attack surface — from the tj-actions compromise to script injection — and gives you copy-paste hardening, OIDC, and scanning.
How to Build a Secure npm Package (2026)
A practical checklist for shipping an npm package that resists supply chain attacks: provenance, granular tokens, minimal published files, no install scripts, and ReDoS-safe code.
How to Check if an npm Package Is Safe
Before you run npm install, learn a quick, repeatable routine to judge whether an npm package is trustworthy — using metadata, known vulnerabilities, and a scan.
How to Generate an SBOM: A Step-by-Step Guide
Produce a spec-compliant CycloneDX or SPDX software bill of materials from any repository in minutes, validate it, and attach it to a release — with real commands you can run today.
npm-check-updates: A Safe Dependency Upgrade Workflow
npm check updates (ncu) shows you every dependency with a newer version than your ranges allow. The tool is simple; the workflow around it is what keeps upgrades from breaking prod.
Prisma Cloud vs Wiz: Supply Chain Features
Both Prisma Cloud and Wiz have expanded into supply chain territory from cloud security origins. A head-to-head on what each actually delivers on the supply chain dimension.
node-sass Is End-of-Life: What That Means and How to Migrate to Dart Sass
node-sass reached end-of-life in 2024 and no longer receives updates or Node.js support. Here is why it was deprecated, what the risk is, and how to migrate to Dart Sass in an afternoon.
Patch the Planet: What AI-Generated Fixes Actually Mean for Open-Source Maintainers
OpenAI's Patch the Planet, co-founded with Trail of Bits, wants to move widely-used open-source projects from findings to fixes. The ambition is right — but it shifts the bottleneck to maintainer review, patch provenance, and the trust of machine-authored code.
What Is a Claude Code Skill, and How Do You Secure One?
A Claude Code skill is a folder of Markdown instructions and scripts that an AI agent loads on demand. Because it can carry executable code, it deserves the same review as any dependency.
Supply Chain Attack Trends: Q3 2025
A data-led look at software supply chain attacks in Q3 2025: npm maintainer phishing, VS Code extension abuse, and a quiet shift toward CI/CD targeting.
Shai-Hulud: The Self-Replicating npm Worm That Hit 500+ Packages
On September 15, 2025, a self-replicating npm worm dubbed Shai-Hulud backdoored more than 500 packages, including @ctrl/tinycolor and CrowdStrike libraries, by pivoting through stolen publish tokens.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.